Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-07-11 CVE-2022-31553 Path Traversal vulnerability in Sleep Learner Project Sleep Learner 20210221
The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
sleep-learner-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31554 Path Traversal vulnerability in Movie-Review-Sentiment-Analysis Project Movie-Review-Sentiment-Analysis 20170507
The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
movie-review-sentiment-analysis-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31555 Path Traversal vulnerability in Nurse Quest Project Nurse Quest 20180222
The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
nurse-quest-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31556 Path Traversal vulnerability in Trainenergyserver Project Trainenergyserver 20170803
The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
trainenergyserver-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31557 Path Traversal vulnerability in Golem Project Golem 20160517
The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
golem-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31558 Path Traversal vulnerability in Shiva-Server Project Shiva-Server
The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
shiva-server-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31559 Path Traversal vulnerability in Flask-Yeoman Project Flask-Yeoman 20130913
The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
flask-yeoman-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31560 Path Traversal vulnerability in Photo TAG Project Photo TAG 20200831
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
photo-tag-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31561 Path Traversal vulnerability in Sphere Imagebackend Project Sphere Imagebackend 20191003
The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
sphere-imagebackend-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31562 Path Traversal vulnerability in Internshipsystem Project Internshipsystem 20180522
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
internshipsystem-project CWE-22
critical
9.3